U.S. Sanctions VPN Provider and Associates for Enabling Ransomware Attacks
The U.S. Treasury Department imposed sanctions on Monday against First VPN Service (1VPNS) and its Ukrainian administrator, Dmytro Rashevskyi, for facilitating ransomware operations targeting American municipalities, hospitals, schools, and businesses. The VPN provider supplied cybercriminals with tools to conceal their identities, disguise malware, and evade detection contributing to billions in losses for U.S. critical infrastructure.
Rashevskyi allegedly used fake identities to purchase infrastructure from providers that would otherwise reject his business due to abuse complaints linked to 1VPNS servers. Additionally, Belarusian national Yegeniy Vladimirovich Silayev was sanctioned for selling "cryptors" tools that cloak malware as harmless files to bypass security measures. Silayev has no direct ties to First VPN.
The sanctions prohibit U.S. entities from engaging in transactions with the designated individuals and entities, dealing a reputational and financial blow. In May, European law enforcement and the FBI dismantled First VPN, citing its long history as a hub for cybercriminals conducting fraud, ransomware attacks, and other illicit activities. The service, active since 2014, was heavily promoted on Russian cybercrime forums and the dark web, marketed for its no-logging policy and refusal to cooperate with law enforcement.
While VPNs are commonly used for privacy, First VPN was exploited to support botnets, scammers, and ransomware gangs. The Treasury emphasized that targeting infrastructure providers and tool suppliers disrupts multiple cybercriminal operations simultaneously. Though the specific ransomware groups using First VPN were not named, the service was a known source of internet infrastructure for malicious actors.
Source: https://therecord.media/first-vpn-administrator-us-sanctions-ransomware-groups
Office of Technical Assistance, U.S. Department of Treasury cybersecurity rating report: https://www.rankiteo.com/company/office-of-technical-assistance-u.s.-department-of-treasury
"id": "OFF1783974298",
"linkid": "office-of-technical-assistance-u.s.-department-of-treasury",
"type": "Ransomware",
"date": "5/2026",
"severity": "100",
"impact": "6",
"explanation": "Attack threatening the economy of geographical region"
{'affected_entities': [{'industry': 'Technology/Internet Services',
'location': 'Global (Operated from Ukraine/Belarus)',
'name': 'First VPN Service (1VPNS)',
'type': 'VPN Provider'},
{'industry': 'Public Sector',
'location': 'United States',
'name': 'American Municipalities',
'type': 'Government'},
{'industry': 'Healthcare',
'location': 'United States',
'name': 'Hospitals',
'type': 'Healthcare'},
{'industry': 'Education',
'location': 'United States',
'name': 'Schools',
'type': 'Education'},
{'industry': 'Various',
'location': 'United States',
'name': 'Businesses',
'type': 'Private Sector'}],
'attack_vector': 'VPN Infrastructure Abuse, Malware Cryptors',
'description': 'The U.S. Treasury Department imposed sanctions on First VPN '
'Service (1VPNS) and its Ukrainian administrator, Dmytro '
'Rashevskyi, for facilitating ransomware operations targeting '
'American municipalities, hospitals, schools, and businesses. '
'The VPN provider supplied cybercriminals with tools to '
'conceal their identities, disguise malware, and evade '
'detection, contributing to billions in losses for U.S. '
'critical infrastructure. Additionally, Belarusian national '
'Yegeniy Vladimirovich Silayev was sanctioned for selling '
"'cryptors' tools that cloak malware as harmless files to "
'bypass security measures.',
'impact': {'brand_reputation_impact': 'Reputational and financial blow to '
'1VPNS',
'financial_loss': 'Billions in losses for U.S. critical '
'infrastructure',
'systems_affected': ['Municipalities',
'Hospitals',
'Schools',
'Businesses']},
'investigation_status': 'Ongoing (1VPNS dismantled in May)',
'motivation': 'Financial Gain',
'post_incident_analysis': {'corrective_actions': 'Sanctions, infrastructure '
'dismantling, and '
'prohibition of transactions '
'with designated entities',
'root_causes': 'Abuse of VPN infrastructure for '
'cybercriminal activities, lack of '
'cooperation with law enforcement, '
'and sale of malware cryptors'},
'references': [{'source': 'U.S. Treasury Department'},
{'source': 'European Law Enforcement and FBI'}],
'regulatory_compliance': {'fines_imposed': 'Sanctions imposed by U.S. '
'Treasury',
'legal_actions': 'Sanctions prohibit U.S. entities '
'from transactions with designated '
'individuals/entities'},
'response': {'containment_measures': 'Dismantling of 1VPNS infrastructure',
'law_enforcement_notified': 'Yes',
'third_party_assistance': 'European law enforcement and FBI'},
'threat_actor': ['Dmytro Rashevskyi',
'Yegeniy Vladimirovich Silayev',
'Cybercriminals using 1VPNS'],
'title': 'U.S. Sanctions VPN Provider and Associates for Enabling Ransomware '
'Attacks',
'type': 'Ransomware Enablement'}